duplicate-disabled-379532.invalid
This domain, www.xeno.rest, is under investigation as an active phishing threat.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
This domain, www.xeno.rest, is under investigation as an active phishing threat. Registered on January 28, 2026, through Global Domain Group LLC, it currently resolves to the IP address 172.67.145.43, which is part of Cloudflare's infrastructure, as confirmed by the nameservers paul.ns.cloudflare.com and sandy.ns.cloudflare.com. Analysis indicates the domain remains operational, with no evidence of takedown or deactivation as of August 6, 2026. VirusTotal telemetry shows that 14 out of 91 security vendors have flagged this domain, though the specific detection categories and payloads are not publicly detailed.
The domain appears on at least one security blocklist, and it has been preemptively blocked by PhishDestroy. No additional context regarding the targeted brand, phishing kit, or scam type is available at this time, and the exact content of the site has not been analyzed. The domain's registration age—approximately six months—does not inherently indicate malicious intent but aligns with common phishing lifecycle patterns. Defenders are advised to treat this domain as high-risk.
Network-level blocking of 172.67.145.43 and the domain itself is recommended for enterprise environments. Security teams should monitor for connections to this IP or domain in logs, particularly those involving credential submission or sensitive data transmission. If internal telemetry confirms user interaction with www.xeno.rest, initiate standard incident response procedures, including password resets and multi-factor authentication enforcement for affected accounts. Further analysis of the site's payload may provide additional indicators of compromise.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Detection-evasion analysis
Cloaking and traffic-distribution check
Not yet scanned
No crawler-versus-browser difference has been recorded yet
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: alive_content: raw=waf_403; http=403; via=https_proxy; server=cloudflare
Stored Capture · 4 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 3 identified
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive